Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1353 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 11% | 💥 PoC | Node-postgres PG | 7/6/2018 | 17/6/2026 | A remote code execution vulnerability was found within the pg module when the remote database or query specifies a specially crafted column name. There are 2 likely scenarios in which one would likely be vulnerable. 1) Executing unsafe, user-supplied sql which contains a malicious column name. 2) Connecting to an… | |
| Modificada | Alta (7.5) | 1.1% | — | Nodesass Project Nodesass | 7/6/2018 | 17/6/2026 | nodesass was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |
| Modificada | Alta (7.5) | 1.1% | — | Noderequest Project Noderequest | 7/6/2018 | 17/6/2026 | noderequest was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |
| Modificada | Alta (7.5) | 1.2% | — | Nodemailer.js Project Nodemailer.js | 7/6/2018 | 17/6/2026 | nodemailer.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |
| Modificada | Alta (7.5) | 1.1% | — | Nodemailer-js Project Nodemailer-js | 7/6/2018 | 17/6/2026 | nodemailer-js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |
| Modificada | Alta (7.5) | 1.2% | — | Nodecaffe Project Nodecaffe | 7/6/2018 | 17/6/2026 | nodecaffe was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |
| Modificada | Alta (7.5) | 1.2% | — | Nodeffmpeg Project Nodeffmpeg | 7/6/2018 | 17/6/2026 | nodeffmpeg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |
| Modificada | Alta (7.5) | 1.1% | — | Node-opencv Project Node-opencv | 7/6/2018 | 17/6/2026 | node-opencv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |
| Modificada | Alta (7.5) | 1.2% | — | Node-openssl Project Node-openssl | 7/6/2018 | 17/6/2026 | node-openssl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |
| Modificada | Alta (7.5) | 1.1% | — | Node-opensl Project Node-opensl | 7/6/2018 | 17/6/2026 | node-opensl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |
| Modificada | Alta (7.5) | 1.1% | — | Mssql-node Project Mssql-node | 7/6/2018 | 17/6/2026 | mssql-node was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |
| Modificada | Alta (7.5) | 1.1% | — | Nodemssql Project Nodemssql | 7/6/2018 | 17/6/2026 | nodemssql was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |
| Modificada | Alta (7.5) | 1.2% | — | Nodefabric Project Nodefabric | 4/6/2018 | 17/6/2026 | `nodefabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |
| Modificada | Alta (7.5) | 1.2% | — | Node-fabric Project Node-fabric | 4/6/2018 | 17/6/2026 | `node-fabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |
| Modificada | Alta (7.5) | 1.2% | — | Nodesqlite Project Nodesqlite | 4/6/2018 | 17/6/2026 | `nodesqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |
| Modificada | Alta (7.5) | 1.2% | — | Node-sqlite Project Node-sqlite | 4/6/2018 | 17/6/2026 | `node-sqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |
| Modificada | Media (6.5) | 2.6% | — | Sync-exec Project Sync-execNodejs Node.js | 4/6/2018 | 17/6/2026 | The sync-exec module is used to simulate child_process.execSync in node versions <0.11.9. Sync-exec uses tmp directories as a buffer before returning values. Other users on the server have read access to the tmp directory, possibly allowing an attacker on the server to obtain confidential information from the… | |
| Modificada | Media (5.9) | 0.93% | — | Cisco Node-jose | 4/6/2018 | 17/6/2026 | node-jose is a JavaScript implementation of the JSON Object Signing and Encryption (JOSE) for current web browsers and node.js-based servers. node-jose earlier than version 0.9.3 is vulnerable to an invalid curve attack. This allows an attacker to recover the private secret key when JWE with Key Agreement with… | |
| Modificada | Alta (8.1) | 2.2% | — | Node-wixtoolset Project Node-wixtoolset | 4/6/2018 | 17/6/2026 | wixtoolset is a Node module wrapper around the wixtoolset binaries wixtoolset downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the… | |
| Modificada | Alta (8.1) | 1.8% | — | Node-air-sdk Project Node-air-sdk | 4/6/2018 | 17/6/2026 | node-air-sdk is an AIR SDK for nodejs. node-air-sdk downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in… | |
| Modificada | Alta (8.1) | 0.58% | — | Node-bsdiff-android Project Node-bsdiff-android | 4/6/2018 | 17/6/2026 | node-bsdiff-android downloads resources over HTTP, which leaves it vulnerable to MITM attacks. | |
| Modificada | Alta (8.1) | 1.8% | — | Geohey Node-thulac | 4/6/2018 | 17/6/2026 | node-thulac is a node binding for thulac. node-thulac downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in… | |
| Modificada | Alta (8.1) | 2.0% | — | Nodeschnaps Project Nodeschnaps | 1/6/2018 | 17/6/2026 | nodeschnaps is a NodeJS compatibility layer for Java (Rhino). nodeschnaps downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network… | |
| Modificada | Alta (8.1) | 1.7% | — | Atom-node-module-installer Project Atom-node-module-installer | 1/6/2018 | 17/6/2026 | atom-node-module-installer installs node modules for atom-shell applications. atom-node-module-installer binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the… | |
| Modificada | Alta (8.1) | 0.58% | — | Node-browser Project Node-browser | 1/6/2018 | 17/6/2026 | node-browser is a wrapper webdriver by nodejs. node-browser downloads resources over HTTP, which leaves it vulnerable to MITM attacks. |